---
title: "CVE-2020-11022"
canonical: "https://kb.cynergy.app/space/MD/899350958/CVE-2020-11022"
format: markdown
---
**Description:**

In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.tion layer.

**Published On:**

2020-04-23

**Updated On:**

4/23/2020

**Trending:**

FALSE

**CWE:**

CWE-79

**Mitigation:**

![image](media://0faac892-8279-4f63-9d9d-f2a282b6de52)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| RHSA-2020:3936 | OpenSource | ipa-4.6.8-5.el7 | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| RHSA-2020:4847 | apache | jss-4.7.3-1.module+el8.3.0+8058+d5cd4219 | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| RHSA-2020:4670 | OpenSource | bind-dyndb-ldap-11.3-1.module+el8.3.0+6993+104f8db0 | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| openSUSE-SU-2020:1060-1 | suse | Security update for cacti, cacti-spine | This update for cacti, cacti-spine fixes the following issues:<br>- cacti 1.2.13:<br>- Query XSS vulnerabilities require vendor package update<br>(CVE-2020-11022 / CVE-2020-11023)<br>- Lack of escaping on some pages can lead to XSS exposure
- Update PHPMailer to 6.1.6 (CVE-2020-13625)
- SQL Injection vulnerability due to input validation failure when<br>editing colors (CVE-2020-14295, boo#1173090)<br>- Lack of escaping on template import can lead to XSS exposure<br>- switch from cron to systemd timers (boo#1115436):<br>+ cacti-cron.timer  
  + cacti-cron.service<br>- avoid potential root escalation on systems with fs.protected_hardlinks=0<br>(boo#1154087): handle directory permissions in file section instead  
  of using chown during post installation<br>- rewrote apache configuration to get rid of .htaccess files and<br>explicitely disable directory permissions per default   
  (only allow a limited, well-known set of directories) | 2020-07-28 | [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html) |
| RHSA-2020:2217 | redhat | Red Hat Security Advisory: OpenShift Container Platform 3.11 security update | Red Hat OpenShift Container Platform release 3.11.219 is now available with  
updates to packages and images that fix several bugs and add enhancements.<br>Red Hat Product Security has rated this update as having a security impact  
of Moderate. A Common Vulnerability Scoring System (CVSS) base score,  
which gives a detailed severity rating, is available for each vulnerability  
from the CVE link(s) in the References section. | 2020-05-29 | [https://access.redhat.com/errata/RHSA-2020:2217](https://access.redhat.com/errata/RHSA-2020:2217) |
| RHSA-2020:2362 | redhat | Red Hat Security Advisory: Red Hat OpenShift Service Mesh security update | An update for jaeger, kiali, and servicemesh-grafana is now available for OpenShift Service Mesh 1.0.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-06-03 | [https://access.redhat.com/errata/RHSA-2020:2362](https://access.redhat.com/errata/RHSA-2020:2362) |
| RHSA-2020:2412 | redhat | Red Hat Security Advisory: OpenShift Container Platform 4.5 container image security update | An update is now available for Red Hat OpenShift Container Platform 4.5.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-07-14 | [https://access.redhat.com/errata/RHSA-2020:2412](https://access.redhat.com/errata/RHSA-2020:2412) |
| RHSA-2020:3247 | redhat | Red Hat Security Advisory: RHV Manager (ovirt-engine) 4.4 security, bug fix, and enhancement update | Updated ovirt-engine packages that fix several bugs and add various enhancements are now available.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-08-05 | [https://access.redhat.com/errata/RHSA-2020:3247](https://access.redhat.com/errata/RHSA-2020:3247) |
| RHSA-2020:3807 | redhat | Red Hat Security Advisory: Red Hat Virtualization security, bug fix, and enhancement update | An update is now available for Red Hat Virtualization Engine 4.4.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-09-24 | [https://access.redhat.com/errata/RHSA-2020:3807](https://access.redhat.com/errata/RHSA-2020:3807) |
| RHSA-2020:3936 | redhat | Red Hat Security Advisory: ipa security, bug fix, and enhancement update | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-10 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| RHSA-2020:4211 | redhat | Red Hat Security Advisory: Red Hat AMQ Interconnect 1.9.0 release and security update | Red Hat AMQ Interconnect 1.9.0 release packages are available for A-MQ Interconnect on RHEL 6, 7, and 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-10 | [https://access.redhat.com/errata/RHSA-2020:4211](https://access.redhat.com/errata/RHSA-2020:4211) |
| RHSA-2020:4298 | redhat | Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update | An update is now available for Red Hat OpenShift Container Platform 4.6.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-29 | [https://access.redhat.com/errata/RHSA-2020:4298](https://access.redhat.com/errata/RHSA-2020:4298) |
| RHSA-2020:4670 | redhat | Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| RHSA-2020:4847 | redhat | Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| RHSA-2020:5249 | redhat | Red Hat Security Advisory: security update - Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container | Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container | 2020-12-01 | [https://access.redhat.com/errata/RHSA-2020:5249](https://access.redhat.com/errata/RHSA-2020:5249) |
| RHSA-2021:0778 | redhat | Red Hat Security Advisory: Red Hat Ansible Tower 3.6.7-1 - Container security and bug fix update | Red Hat Ansible Tower 3.6.7-1 - RHEL7 Container<br>Red Hat Product Security has rated this update as having a security impact of  
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-03-10 | [https://access.redhat.com/errata/RHSA-2021:0778](https://access.redhat.com/errata/RHSA-2021:0778) |
| FEDORA-2020-0b32a59b54 | fedora | Fedora 32 Update: drupal7-7.72-1.fc32 | - [https://www.drupal.org/project/drupal/releases/7.72](https://www.drupal.org/project/drupal/releases/7.72)      - [Drupal core -<br>Critical - Cross Site Request Forgery - SA-  
CORE-2020-004]([https://www.drupal.org/sa-core-2020-004](https://www.drupal.org/sa-core-2020-004) ) / CVE-2020-13663 -  
[https://www.drupal.org/project/drupal/releases/7.71](https://www.drupal.org/project/drupal/releases/7.71)  -  
[https://www.drupal.org/project/drupal/releases/7.70](https://www.drupal.org/project/drupal/releases/7.70)      - [Drupal core -  
Moderately critical - Cross Site Scripting - SA-  
CORE-2020-002]([https://www.drupal.org/sa-core-2020-002](https://www.drupal.org/sa-core-2020-002) ) / CVE-2020-11022 /  
CVE-2020-11023     - [Drupal core - Moderately critical - Open Redirect - SA-  
CORE-2020-003]([https://www.drupal.org/sa-core-2020-003](https://www.drupal.org/sa-core-2020-003) ) / CVE-2020-13662 | 2020-09-14 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-0b32a59b54](https://bodhi.fedoraproject.org/updates/FEDORA-2020-0b32a59b54) |
| FEDORA-2020-11be4b36d4 | fedora | Fedora 32 Update: drupal7-7.70-1.fc32 | Security fix for [https://www.drupal.org/sa-core-2020-002](https://www.drupal.org/sa-core-2020-002)  and  
[https://www.drupal.org/sa-core-2020-003](https://www.drupal.org/sa-core-2020-003) | 2020-05-31 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-11be4b36d4](https://bodhi.fedoraproject.org/updates/FEDORA-2020-11be4b36d4) |
| FEDORA-2020-36d2db5f51 | fedora | Fedora 32 Update: drupal8-8.9.0-1.fc32 | - [https://www.drupal.org/project/drupal/releases/8.9.0](https://www.drupal.org/project/drupal/releases/8.9.0)  -<br>[https://www.drupal.org/project/drupal/releases/8.8.7](https://www.drupal.org/project/drupal/releases/8.8.7)  -  
[https://www.drupal.org/project/drupal/releases/8.8.6](https://www.drupal.org/project/drupal/releases/8.8.6)      - [SA-  
CORE-2020-002]([https://www.drupal.org/sa-core-2020-002](https://www.drupal.org/sa-core-2020-002) ) /  
[CVE-2020-11022]([https://nvd.nist.gov/vuln/detail/CVE-2020-11022](https://nvd.nist.gov/vuln/detail/CVE-2020-11022) ) /  
[CVE-2020-11023]([https://nvd.nist.gov/vuln/detail/CVE-2020-11023](https://nvd.nist.gov/vuln/detail/CVE-2020-11023) ) -  
[https://www.drupal.org/project/drupal/releases/8.8.5](https://www.drupal.org/project/drupal/releases/8.8.5) | 2020-06-16 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-36d2db5f51](https://bodhi.fedoraproject.org/updates/FEDORA-2020-36d2db5f51) |
| FEDORA-2020-fbb94073a1 | fedora | Fedora 31 Update: drupal7-7.72-1.fc31 | - [https://www.drupal.org/project/drupal/releases/7.72](https://www.drupal.org/project/drupal/releases/7.72)      - [Drupal core -<br>Critical - Cross Site Request Forgery - SA-  
CORE-2020-004]([https://www.drupal.org/sa-core-2020-004](https://www.drupal.org/sa-core-2020-004) ) / CVE-2020-13663 -  
[https://www.drupal.org/project/drupal/releases/7.71](https://www.drupal.org/project/drupal/releases/7.71)  -  
[https://www.drupal.org/project/drupal/releases/7.70](https://www.drupal.org/project/drupal/releases/7.70)      - [Drupal core -  
Moderately critical - Cross Site Scripting - SA-  
CORE-2020-002]([https://www.drupal.org/sa-core-2020-002](https://www.drupal.org/sa-core-2020-002) ) / CVE-2020-11022 /  
CVE-2020-11023     - [Drupal core - Moderately critical - Open Redirect - SA-  
CORE-2020-003]([https://www.drupal.org/sa-core-2020-003](https://www.drupal.org/sa-core-2020-003) ) / CVE-2020-13662 | 2020-09-14 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-fbb94073a1](https://bodhi.fedoraproject.org/updates/FEDORA-2020-fbb94073a1) |
| FEDORA-2020-fe94df8c34 | fedora | Fedora 33 Update: drupal7-7.72-1.fc33 | - [https://www.drupal.org/project/drupal/releases/7.72](https://www.drupal.org/project/drupal/releases/7.72)      - [Drupal core -<br>Critical - Cross Site Request Forgery - SA-  
CORE-2020-004]([https://www.drupal.org/sa-core-2020-004](https://www.drupal.org/sa-core-2020-004) ) / CVE-2020-13663 -  
[https://www.drupal.org/project/drupal/releases/7.71](https://www.drupal.org/project/drupal/releases/7.71) | 2020-10-10 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-fe94df8c34](https://bodhi.fedoraproject.org/updates/FEDORA-2020-fe94df8c34) |
| openSUSE-SU-2020:1060-1 | suse | Security update for cacti, cacti-spine | This update for cacti, cacti-spine fixes the following issues:<br>- cacti 1.2.13:<br>- Query XSS vulnerabilities require vendor package update<br>(CVE-2020-11022 / CVE-2020-11023)<br>- Lack of escaping on some pages can lead to XSS exposure
- Update PHPMailer to 6.1.6 (CVE-2020-13625)
- SQL Injection vulnerability due to input validation failure when<br>editing colors (CVE-2020-14295, boo#1173090)<br>- Lack of escaping on template import can lead to XSS exposure<br>- switch from cron to systemd timers (boo#1115436):<br>+ cacti-cron.timer  
  + cacti-cron.service<br>- avoid potential root escalation on systems with fs.protected_hardlinks=0<br>(boo#1154087): handle directory permissions in file section instead  
  of using chown during post installation<br>- rewrote apache configuration to get rid of .htaccess files and<br>explicitely disable directory permissions per default   
  (only allow a limited, well-known set of directories) | 2021-04-17 | [https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html](https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html) |
| openSUSE-SU-2020:1106-1 | suse | Security update for cacti, cacti-spine | This update for cacti, cacti-spine fixes the following issues:<br>- cacti 1.2.13:<br>- Query XSS vulnerabilities require vendor package update<br>(CVE-2020-11022 / CVE-2020-11023)<br>- Lack of escaping on some pages can lead to XSS exposure
- Update PHPMailer to 6.1.6 (CVE-2020-13625)
- SQL Injection vulnerability due to input validation failure when<br>editing colors (CVE-2020-14295, boo#1173090)<br>- Lack of escaping on template import can lead to XSS exposure<br>- switch from cron to systemd timers (boo#1115436):<br>+ cacti-cron.timer  
  + cacti-cron.service<br>- avoid potential root escalation on systems with fs.protected_hardlinks=0<br>(boo#1154087): handle directory permissions in file section instead  
  of using chown during post installation<br>- rewrote apache configuration to get rid of .htaccess files and<br>explicitely disable directory permissions per default   
  (only allow a limited, well-known set of directories)<br>This update was imported from the openSUSE:Leap:15.1:Update update project. | 2022-03-25 | [https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html](https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html) |
| openSUSE-SU-2020:1888-1 | suse | Security update for otrs | This update for otrs fixes the following issues:<br>- otrs was updated to 6.0.30 (OSA-2020-14 boo#1178434)
- CVE-2020-11022, CVE-2020-11023: Vulnerability in third-party library - jquery<br>OTRS uses jquery version 3.4.1, which is vulnerable to cross-site scripting   
    (XSS). | 2021-03-26 | [https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html](https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html) |
| glsa202007-03 | gentoo | Cacti: Multiple vulnerabilities | <p>Multiple vulnerabilities have been discovered in Cacti. Please review  
      the CVE identifiers referenced below for details.  
    </p> | 2020-07-29 | [https://security.gentoo.org/glsa/202007-03](https://security.gentoo.org/glsa/202007-03) |
| CPUApr2021 | oracle | Oracle Critical Patch Update Advisory - April 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-05-06 | [https://www.oracle.com/security-alerts/cpuapr2021.html](https://www.oracle.com/security-alerts/cpuapr2021.html) |
| CPUApr2022 | oracle | Oracle Critical Patch Update Advisory - April 2022 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2022-05-06 | [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html) |
| CPUJan2021 | oracle | Oracle Critical Patch Update Advisory - January 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-05-06 | [https://www.oracle.com/security-alerts/cpujan2021.html](https://www.oracle.com/security-alerts/cpujan2021.html) |
| CPUJan2022 | oracle | Oracle Critical Patch Update Advisory - January 2022 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2022-03-25 | [https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html) |
| CPUJul2020 | oracle | Oracle Critical Patch Update Advisory - July 2020 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2020-09-06 | [https://www.oracle.com/security-alerts/cpujul2020.html](https://www.oracle.com/security-alerts/cpujul2020.html) |
| CPUJul2021 | oracle | Oracle Critical Patch Update Advisory - July 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-08-25 | [https://www.oracle.com/security-alerts/cpujul2021.html](https://www.oracle.com/security-alerts/cpujul2021.html) |
| CPUOct2020 | oracle | Oracle Critical Patch Update Advisory - October 2020 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2020-11-06 | [https://www.oracle.com/security-alerts/cpuoct2020.html](https://www.oracle.com/security-alerts/cpuoct2020.html) |
| CPUOct2021 | oracle | Oracle Critical Patch Update Advisory - October 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-11-06 | [https://www.oracle.com/security-alerts/cpuoct2021.html](https://www.oracle.com/security-alerts/cpuoct2021.html) |
| SUSE-SU-2020:2292-1 | suse | Security update for SUSE Manager Proxy 3.2 | This update fixes the following issues:<br>release-notes-susemanager-proxy:<br>- Update to 3.2.15
- Bugs mentioned<br>bsc#1174965, bsc#1170331, bsc#1159184, bsc#1171169, bsc#1166284, bsc#1174768, bsc#1172831, bsc#1172462<br>spacewalk-backend:<br>- Fix issues importing RPM packages with long RPM headers (bsc#1174965)
- Do not make mgr-inter-sync to crash if there are non-ASCII<br>characters on an exception message (bsc#1170331)<br>- Validate cached package entries on ISS slave (bsc#1159184)<br>spacewalk-client-tools:<br>- Do not crash 'mgr-update-status' because 'long' type is not defined in Python 3<br>spacewalk-proxy-installer:<br>- Do not cache metadata of the bootstrap repositories (bsc#1171169)
- Move vital proxy templates to a safe place outside of docu (bsc#1166284)<br>spacewalk-web:<br>- Fix saving of formulas (bsc#1174768)
- Upgrade jQuery and adapt the code - CVE-2020-11022 (bsc#1172831)<br>zypp-plugin-spacewalk:<br>- Prevent issue with non-ASCII characters in Python 2 systems (bsc#1172462)<br>How to apply this update:<br>1. Log in as root user to the SUSE Manager proxy.
2. Stop the proxy service:<br>spacewalk-proxy stop<br>1. Apply the patch using either zypper patch or YaST Online Update.
2. Start the Spacewalk service:<br>spacewalk-proxy start | 2021-03-26 | [https://www.suse.com/support/update/announcement/2020/suse-su-20202292-1/](https://www.suse.com/support/update/announcement/2020/suse-su-20202292-1/) |
| SUSE-SU-2020:2373-1 | suse | Security update for SUSE Manager Server 4.1 | This update fixes the following issues:<br>cobbler:<br>- More old modules naming fixes (bsc#1169553)<br>image-sync-formula:<br>- Allow image-sync state on regular minion.<br>Image sync state requires branch-network pillars to get the directory  
  where to sync images. Use default `/srv/saltboot` if that pillar is  
  missing so image-sync can be applied on non branch minions as well.<br>mgr-libmod:<br>- Remove unnecessary array wrap in 'list_modules' response object<br>mgr-osad:<br>- Move uyuni-base-common dependency from mgr-osad to mgr-osa-dispatcher<br>(bsc#1174405)<br>openvpn-formula:<br>- Add hint that ssl certs must be on system (bsc#1172279)<br>patterns-suse-manager:<br>- Add Recommends for golang-github-QubitProducts-exporter_exporter<br>prometheus-exporters-formula:<br>- Bugfix: Handle exporters proxy for unsupported distros (bsc#1175555)
- Add support for exporters proxy (exporter_exporter)<br>pxe-default-image-sle15:<br>- Rollback the workaround for bsc#1172807, as dracut is now fixed<br>saltboot-formula:<br>- Better fix for rounding errors (bsc#1136857)<br>spacecmd:<br>- Fix softwarechannel update for vendor channels (bsc#1172709)
- Fix escaping of package names (bsc#1171281)<br>spacewalk-backend:<br>- Adds basic functionality for gpg check
- Verify GPG signature of Ubuntu/Debian repository metadata (Release file)
- Take care of SCC auth tokens on DEB repos GPG checks (bsc#1175485)
- Use spacewalk keyring for GPG checks on DEB repos (bsc#1175485)<br>spacewalk-branding:<br>- Implement Maintenance Windows
- Fix typo on spacewalk-branding license<br>spacewalk-certs-tools:<br>- Strip SSL Certificate Common Name after 63 Characters (bsc#1173535)
- Fix centos detection (bsc#1173584)<br>spacewalk-java:<br>- Use media.1/products from media when not specified different (bsc#1175558)
- Upgrade jQuery and adapt the code - CVE-2020-11022 (bsc#1172831)
- Fix error when rolling back a system to a snapshot (bsc#1173997)
- Implement maintenance windows backend
- Add check for maintainence window during executing recurring actions
- Implement maintenance windows in struts
- XMLRPC: Assign/retract maintenance schedule to/from systems
- Fix softwarechannel update for vendor channels (bsc#1172709)
- Avoid deadlock when syncing channels and registering minions at the same time (bsc#1173566)
- Change system list header text to something better (bsc#1173982)
- Set CPU and memory info for virtual instances (bsc#1170244)
- Add virtual network Start, Stop and Delete actions
- Add virtual network list page
- Fix httpcomponents and gson jar symlinks (bsc#1174229)
- Enhance RedHat product detection for CentOS and OracleLinux (bsc#1173584)
- Provide comps.xml and modules.yaml when using onlinerepo for kickstart
- Refresh virtualization pages only on events
- Fix up2date detection on RH8 when salt-minion is used for registration
- Improve performance of the System Groups page with many clients (bsc#1172839)
- Include number of non-patch package updates to non-critical update counts<br>in system group pages (bsc#1170468)<br>- Bump XMLRPC API version number to distinguish from Spacewalk 2.10
- Cluster UI: return to overview page after scheduling actions
- Fix NPE on auto installation when no kernel options are given (bsc#1173932)
- Fix issue with disabling self_update for autoyast autoupgrade (bsc#1170654)
- Adapt expectations for jobs return events after switching Salt<br>states to use 'mgrcompat.module_run' state.<br>spacewalk-utils:<br>- Add aarch64 for openSUSE Leap 15.1 and 15.2<br>spacewalk-web:<br>- Upgrade jQuery and adapt the code - CVE-2020-11022 (bsc#1172831)
- Fix JS linting errors/warnings
- Enable Nutanix AHV virtual host gatherer.
- Web UI: Implement managing maintenance schedules and calendars
- Warn when a system is in multiple groups that configure the same<br>formula in the system formula's UI (bsc#1173554)<br>- Add virtual network start, stop and delete actions
- Add virtual network list page
- Fix internal server error when creating module filters in CLM (bsc#1174325)
- Fix VM creation page when there is no volume in the default storage pool
- Refresh virtualization pages only on events
- Product list in the Wizard doesn't show SLE products first (bsc#1173522)
- Cluster UI: return to overview page after scheduling actions
- Changes in the logic to update the tick icon.
- For the postgres localhost:5432 case, use the
- Fix internal server errors by returning 0 instead of dying
- Add missing dependency to spacewalk-base-minimal (bsc#678126)
- Change kickstart to autoinstallation in navigation on pxt pages
- Debranding<br>suseRegisterInfo:<br>- Enhance RedHat product detection for CentOS and OracleLinux (bsc#1173584)<br>susemanager:<br>- Migrate all occurrences of kickstart to autoinstall in cobbler database (bsc#1169780)
- Define bootstrap repo data for SUSE Manager Proxies (bsc#1174470)
- Add SLE 15 LTSS Product ID to SLE15 bootstrap repositories, as<br>it is required to get python3-M2crypto (bsc#1174167)<br>susemanager-doc-indexes:<br>- Left navigation structure cleaned up
- Fixed several broken xrefs
- Added hostname admonition for public cloud sections
- Clarified Branch Proxy configuration instructions
- Fixed index page pdf links, urls were 1 step to deep
- SUSECOM 2020 branding update
- PDF 2020 branding update
- WEBUI 2020 branding update
- Added maintenance window documentation
- Added SLE client chapter
- Added 508 compliance
- Added reverse proxy information to Monitoring in Admin Guide
- Add note about accessibility to index
- In the Upgrade Guide, use Major, Minor, and Patch Level terminology for versioning.
- Added docs for nutanix VHM
- Ubuntu clients using the CLI in SUMA (bsc#1174025)<br>susemanager-docs_en:<br>- Left navigation structure cleaned up
- Fixed several broken xrefs
- Added hostname admonition for public cloud sections
- Clarified Branch Proxy configuration instructions
- Fixed index page pdf links, urls were 1 step to deep
- SUSECOM 2020 branding update
- PDF 2020 branding update
- WEBUI 2020 branding update
- Added maintenance window documentation
- Added SLE client chapter
- Added 508 compliance
- Added reverse proxy information to Monitoring in Admin Guide
- Add note about accessibility to index
- In the Upgrade Guide, use Major, Minor, and Patch Level terminology for versioning.
- Added docs for nutanix VHM
- Ubuntu clients using the CLI in SUMA (bsc#1174025)<br>susemanager-frontend-libs:<br>- Upgrade jquery to 3.5.1 - CVE-2020-11022 (bsc#1172831)<br>susemanager-schema:<br>- Add new states and types for virtual instances in order<br>to support Nutanix AHV.<br>- Implement Maintenance Windows
- Add virtual network state change action
- Internal fixes to avoid problems with the idempotency tests<br>susemanager-sls:<br>- Fix the dnf plugin to add the token to the HTTP header (bsc#1175724)
- Fix: supply a dnf base when dealing w/repos (bsc#1172504)
- Fix: autorefresh in repos is zypper-only
- Add virtual network state change state to handle start, stop and delete
- Add virtual network state change state to handle start and stop
- Fetch oracle-release when looking for RedHat Product Info (bsc#1173584)
- Force a refresh after deleting a virtual storage volume
- Prevent stuck Hardware Refresh actions on Salt 2016.11.10 based SSH minions (bsc#1173169)
- Require PyYAML version >= 5.1
- Log out of Docker registries after image build (bsc#1165572)
- Prevent 'module.run' deprecation warnings by using custom mgrcompat module<br>susemanager-sync-data:<br>- Remove version from centos and oracle linux identifier (bsc#1173584)<br>uyuni-common-libs:<br>- Fix issues importing RPM packages with long RPM headers (bsc#1174965)<br>virtual-host-gatherer:<br>- Add new gatherer module for Nutanix AHV.<br>virtualization-host-formula:<br>- Ensure kernel-default and libvirt-python3 are installed
- Set bridge network as default
- Fix conditionals (bsc#1175791)<br>yomi-formula:<br>- Update to version 0.0.1+git.1595952633.b300be2:
- pillar: install always kernel-default
- chroot: python3-base is now a capability
- Move systemctl calls inside chroot
- Network: initial work for network declaration
- MicroOS: Remove tmp subvolume
- Update format following the new standard
- Fix __mount_device wrapper<br>httpcomponents-core:<br>- Include the correct package in SUSE Manager Server (no source changes)<br>httpcomponents-client:<br>- Include the correct package in SUSE Manager Server (no source changes)<br>google-gson:<br>- Include the correct package in SUSE Manager Server (no source changes)<br>How to apply this update:<br>1. Log in as root user to the SUSE Manager server.
2. Stop the Spacewalk service:<br>spacewalk-service stop<br>1. Apply the patch using either zypper patch or YaST Online Update.
2. Upgrade the database schema:<br>spacewalk-schema-upgrade<br>1. Start the Spacewalk service:<br>spacewalk-service start | 2020-08-30 | [https://www.suse.com/support/update/announcement/2020/suse-su-20202373-1/](https://www.suse.com/support/update/announcement/2020/suse-su-20202373-1/) |
| SUSE-SU-2020:2650-1 | suse | Security update for SUSE Manager Proxy 4.0 | This update fixes the following issues:<br>spacecmd:<br>- Python3 fixes for errata in spacecmd (bsc#1169664)
- Python3 fix for sorted usage (bsc#1167907)
- Fix softwarechannel_listlatestpackages throwing error on<br>empty channels (bsc#1175889)<br>- Fix escaping of package names (bsc#1171281)<br>spacewalk-certs-tools:<br>- Add option --nostricthostkeychecking to spacewalk-ssh-push-init
- Strip SSL Certificate Common Name after 63 Characters (bsc#1173535)<br>spacewalk-proxy:<br>- Python3 fix for loading pickle file during kickstart<br>procedure (bsc#1174201)<br>spacewalk-web:<br>- Fix login page after jQuery upgrade (bsc#1175224)
- Upgrade jQuery and adapt the code - CVE-2020-11022 (bsc#1172831)
- Warn when a system is in multiple groups that configure the same formula in the system formula's UI (bsc#1173554)<br>How to apply this update:<br>1. Log in as root user to the SUSE Manager proxy.
2. Stop the proxy service:<br>spacewalk-proxy stop<br>1. Apply the patch using either zypper patch or YaST Online Update.
2. Start the Spacewalk service:<br>spacewalk-proxy start | 2021-03-26 | [https://www.suse.com/support/update/announcement/2020/suse-su-20202650-1/](https://www.suse.com/support/update/announcement/2020/suse-su-20202650-1/) |